SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareDanBot | DanBot can upload files from compromised hosts. |
| T1010 Application Window Discovery |
GroupHEXANE | HEXANE has used a PowerShell-based keylogging tool to capture the window title. |
| T1021.001 Remote Desktop Protocol |
GroupHEXANE | HEXANE has used remote desktop sessions for lateral movement. |
| T1027.013 Encrypted/Encoded File |
MalwareDanBot | DanBot can Base64 encode its payload. |
| T1053.005 Scheduled Task |
MalwareDanBot | DanBot can use a scheduled task for installation. |
| T1056.001 Keylogging |
GroupHEXANE | HEXANE has used a PowerShell-based keylogger named `kl.ps1`. |
| T1059.001 PowerShell |
GroupHEXANE | HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareDanBot | DanBot has the ability to execute arbitrary commands via `cmd.exe`. |
| T1059.005 Visual Basic |
MalwareDanBot | DanBot can use a VBA macro embedded in an Excel file to drop the payload. |
| T1071.001 Web Protocols |
MalwareDanBot | DanBot can use HTTP in C2 communication. |
| T1071.004 DNS |
MalwareDanBot | DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications. |
| T1087.002 Domain Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1105 Ingress Tool Transfer |
MalwareDanBot | DanBot can download additional files to a targeted system. |
| T1110 Brute Force |
GroupHEXANE | HEXANE has used brute force attacks to compromise valid credentials. |
| T1110.003 Password Spraying |
GroupHEXANE | HEXANE has used password spraying attacks to obtain valid credentials. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDanBot | DanBot can use a VBA macro to decode its payload prior to installation and execution. |
| T1204.002 Malicious File |
GroupHEXANE | HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware. |
| T1204.002 Malicious File |
MalwareDanBot | DanBot has relied on victims' opening a malicious file for initial execution. |
| T1534 Internal Spearphishing |
GroupHEXANE | HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access. |
| T1555 Credentials from Password Stores |
ToolPoshC2 | PoshC2 can decrypt passwords stored in the RDCMan configuration file. |
| T1566.001 Spearphishing Attachment |
MalwareDanBot | DanBot has been distributed within a malicious Excel attachment via spearphishing emails. |
| T1583.001 Domains |
GroupHEXANE | HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization. |
| T1586.002 Email Accounts |
GroupHEXANE | HEXANE has used compromised accounts to send spearphishing emails. |
| T1588.002 Tool |
GroupHEXANE | HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net. |
| T1589.002 Email Addresses |
GroupHEXANE | HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing. |
| T1591.004 Identify Roles |
GroupHEXANE | HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.